CVE-2026-26064: calibre: Path Traversal Vulnerability Enables Arbitrary File Write and Remote Code Execution
calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Versions 9.2.1 and below contain a Path Traversal vulnerability that allows arbitrary file writes anywhere the user has write permissions. On Windows, this leads to Remote Code Execution by writing a payload to the Startup folder, which executes on next login. Function extractpictures only checks startswith('Pictures'), and does not sanitize '..' sequences. calibre's own ZipFile.extractall() in utils/zipfile.py does sanitize '..' via gettargetpath(), but extractpictures() bypasses this by using manual zf.read() + open(). This issue has been fixed in version 9.3.0.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-26064?
CVE-2026-26064 is classified as a critical vulnerability due to its potential for arbitrary file write and remote code execution.
How do I fix CVE-2026-26064?
To fix CVE-2026-26064, upgrade to calibre version 9.2.2 or later.
What versions of calibre are affected by CVE-2026-26064?
CVE-2026-26064 affects calibre versions 9.2.1 and below.
What type of vulnerability is CVE-2026-26064?
CVE-2026-26064 is a path traversal vulnerability.
What risks does CVE-2026-26064 pose to users?
CVE-2026-26064 poses risks of arbitrary file writes and remote code execution, which can compromise user systems.